Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam NSE4_FGT-7.2 topic 1 question 19 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 19
Topic #: 1
[All NSE4_FGT-7.2 Questions]

Refer to exhibit.
An administrator configured the web filtering profile shown in the exhibit to block access to all social networking sites except Twitter. However, when users try to access twitter.com, they are redirected to a FortiGuard web filtering block page.

Based on the exhibit, which configuration change can the administrator make to allow Twitter while blocking all other social networking sites?

  • A. On the FortiGuard Category Based Filter configuration, set Action to Warning for Social Networking.
  • B. On the Static URL Filter configuration, set Type to Simple.
  • C. On the Static URL Filter configuration, set Action to Exempt.
  • D. On the Static URL Filter configuration, set Action to Monitor.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Spago
Highly Voted 1 year, 3 months ago
Selected Answer: C
C. On the Static URL Filter configuration, set Action to Exempt. Based on the exhibit, the administrator has configured the FortiGuard Category Based Filter to block access to all social networking sites, and has also configured a Static URL Filter to block access to twitter.com. As a result, users are being redirected to a block page when they try to access twitter.com. To allow users to access twitter.com while blocking all other social networking sites, the administrator can make the following configuration change: On the Static URL Filter configuration, set Action to Exempt: By setting the Action to Exempt, the administrator can override the block on twitter.com that was specified in the FortiGuard Category Based Filter. This will allow users to access twitter.com, while all other social networking sites will still be blocked.
upvoted 10 times
...
Imanism
Most Recent 2 months, 3 weeks ago
Selected Answer: C
When FortiGate performs a web filter check, it will first check the static URL filter list (if applied to the profile) and based on the action, will then perform the FortiGuard category check. 'Action' descriptions in Static URL see bellow: - 'Block' -> destination is blocked and session dropped, no further category check is needed. - 'Allow' -> destination is allowed from the static URL list, FortiGate proceeds with checking the category to decide further action. - 'Exempt' -> destination is exempted from further inspection and traffic is allowed.
upvoted 3 times
...
AMK2ENG
4 months ago
C. On the Static URL Filter configuration, set Action to Exempt. Most Voted
upvoted 1 times
...
spydog
5 months, 2 weeks ago
Selected Answer: C
Even that in the GUI static URL filter is configured as part of Web Filter profile in the background they are separate. FortiGate will apply the following order of inspection 1)Static URL -> 2) FortiGuard Category Filter -> 3)Advance Filter. When static URL filter is configured to allow FGT will move to next and check if url is allowed or blocked by FortiGuard categories. Exempt action on static url filter will tell FGT to exempt this url from other inspections, by passing FortiGuard categories.
upvoted 4 times
...
elemzy
6 months, 3 weeks ago
why is everyone choosing C, when the url is not a wildcard. This is a simple entry in the url filter, so change the type to simple. Moreover, static url entry is first checked before others. Also, exempt only means to completely trust the trafficand not pass it through other security check, but here it is still blocked by a webfilter. Meaning something is wrong with the filter definition.
upvoted 2 times
spydog
5 months, 2 weeks ago
As you mentioned static URL filter is applied first, before category filter. Static URL filter has three actions - allow, block and exempt: - If block page is block without checking categories - if allow, page is send for inspection by category filter - if exempt, page is bypassing category filter and displayed to the user.
upvoted 4 times
...
LAFNELL
6 months ago
no Bro it's definitely a wildcard. So i can confirm you the correct answer is C
upvoted 1 times
...
...
aap2023
7 months, 1 week ago
C, but set Action to Exempt.
upvoted 1 times
...
raydel92
7 months, 2 weeks ago
Selected Answer: C
C. On the Static URL Filter configuration, set Action to Exempt. FortiGate Security 7.2 Study Guide (p.269): "Allow: Access is permitted. Traffic is passed to remaining operations, including FortiGuard web filter, web content filter, web script filters, and antivirus scanning. Exempt: Allows traffic from trusted sources to bypass all security inspections." Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html
upvoted 3 times
...
Vic2911
7 months, 3 weeks ago
Selected Answer: C
Correct answer is C: Exempt: when set to exempt, the FortiGate allow the traffic and exempt URL from all further inspection (including FortiGuard catergories which would then block the traffic)
upvoted 2 times
...
Slash_JM
7 months, 3 weeks ago
Selected Answer: C
FortiGate Security 7.2 Study Guide p.269
upvoted 3 times
...
crose
7 months, 4 weeks ago
C: (if its not exempt it will still be blocked in a latter filter) Http inspection order >> URL >> static url filter (block/allow/exempt) -> Fortigate category filter (allow block) advanced filters (block/allow) >> displays page
upvoted 2 times
...
pramodbs
8 months, 2 weeks ago
Answer is B since URL filter is checked before category filter. you have to just change to simple
upvoted 2 times
...
jlarmando85
8 months, 3 weeks ago
Selected Answer: B
I configured this WebFilter on a FGT on Labo and the answer is B. You need to configure to simple to match with: twitter.com. On the other way, URL filter is evaluated before the Category Filter, so when matches it will pass.
upvoted 2 times
...
erawemk
9 months, 4 weeks ago
Selected Answer: C
A. It will allow all social networking sites, it is not correct B. It does not help C. Exempt does allow traffic and not inspect it D. Monitor will allow traffic and log it as well "allow" config that is not working
upvoted 2 times
...
AgentSmith
10 months ago
B is the answer, Simple - Allow. This rule will be hit before the Content Filter
upvoted 1 times
...
felcard_debugs
1 year ago
Selected Answer: C
C is correct
upvoted 1 times
...
PaulGo
1 year ago
Selected Answer: C
Correct C
upvoted 1 times
...
Equiano
1 year, 1 month ago
Selected Answer: C
C is correct! Tested this in a lab environment and to make this work as stated in the question the Exempt action is the only way to go, and also *.twimg.com will has to be added to the URL Filter with an Exempt action for this situation to really work!
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...